Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4800

Опубликовано: 30 мая 2016
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6jetty-eclipseNot affected
Red Hat Enterprise Linux 7jettyNot affected
Red Hat JBoss A-MQ 6jettyNot affected
Red Hat JBoss BRMS 5jettyNot affected
Red Hat JBoss Data Virtualization 6jettyNot affected
Red Hat JBoss Enterprise Application Platform 5jettyNot affected
Red Hat JBoss Fuse 6jettyNot affected
Red Hat JBoss Fuse Service Works 6jettyNot affected
Red Hat JBoss Portal 6jettyNot affected
Red Hat JBoss SOA Platform 5jettyNot affected

Показывать по

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 93%
0.06363
Низкий

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

CVSS3: 9.8
nvd
больше 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

CVSS3: 9.8
debian
больше 9 лет назад

The path normalization mechanism in PathResource class in Eclipse Jett ...

CVSS3: 9.8
github
почти 8 лет назад

Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request

EPSS

Процентиль: 93%
0.06363
Низкий

5 Medium

CVSS2